If a controller becomes aware of a serious personal data breach in relation to personal data for which the controller is responsible, the controller must notify the Commissioner of the breach without undue delay.
Where the notification to the Commissioner is not made within 72 hours, the notification must be accompanied by reasons for the delay.
Subject to subsection (4), the notification must include—
Where and to the extent that it is not possible to provide all the information mentioned in subsection (3) at the same time, the information may be provided in phases without undue further delay.
If a processor becomes aware of a personal data breach (in relation to data processed by the processor), the processor must notify the controller without undue delay.
Subsection (1) does not apply in relation to a personal data breach if the breach also constitutes a relevant error within the meaning given by section 231(9) of the Investigatory Powers Act 2016.
For the purposes of this section, a personal data breach is serious if the breach seriously interferes with the rights and freedoms of a data subject.